Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-5344 |
|
Path Traversal in path-traversal (CVE-2026-5344)
path traversal in path-traversal (CVE-2026-5344). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34973 |
|
Vulnerability in phpmyfaq (CVE-2026-34973)
vulnerability in phpmyfaq (CVE-2026-34973). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34974 |
|
Cross-Site Scripting (XSS) in privilege-escalation (CVE-2026-34974)
cross-site scripting in privilege-escalation (CVE-2026-34974). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3502 KEV |
|
[KEV] Vulnerability in Trueconf client (CVE-2026-3502)
vulnerability in Trueconf client (CVE-2026-3502). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-5272 |
|
Vulnerability in google (CVE-2026-5272)
vulnerability in google (CVE-2026-5272). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5273 |
|
Use-After-Free in google (CVE-2026-5273)
vulnerability in google (CVE-2026-5273). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5281 KEV |
|
[KEV] Use-After-Free in Google dawn (CVE-2026-5281)
vulnerability in Google dawn (CVE-2026-5281). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-34442 |
|
Vulnerability in laravel (CVE-2026-34442)
vulnerability in laravel (CVE-2026-34442). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| CVE-2026-34443 |
|
SSRF (Server-Side Request Forgery) in laravel (CVE-2026-34443)
SSRF in laravel (CVE-2026-34443). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34733 |
|
Vulnerability in wwbn (CVE-2026-34733)
vulnerability in wwbn (CVE-2026-34733). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34737 |
|
Vulnerability in wwbn (CVE-2026-34737)
vulnerability in wwbn (CVE-2026-34737). Data can be tampered with by attackers.
|
| CVE-2026-34739 |
|
Cross-Site Scripting (XSS) in wwbn (CVE-2026-34739)
cross-site scripting in wwbn (CVE-2026-34739). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34740 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34740)
SSRF in ssrf (CVE-2026-34740). Confidential information can be exposed externally.
|
| CVE-2026-34611 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34611)
vulnerability in csrf (CVE-2026-34611). Data can be tampered with by attackers.
|
| CVE-2026-34613 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34613)
vulnerability in csrf (CVE-2026-34613). Data can be tampered with by attackers.
|
| CVE-2026-34731 |
|
Vulnerability in wwbn (CVE-2026-34731)
vulnerability in wwbn (CVE-2026-34731). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34732 |
|
Vulnerability in wwbn (CVE-2026-34732)
vulnerability in wwbn (CVE-2026-34732). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34382 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34382)
vulnerability in csrf (CVE-2026-34382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34384 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34384)
vulnerability in csrf (CVE-2026-34384). Data can be tampered with by attackers.
|
| CVE-2026-34394 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34394)
vulnerability in csrf (CVE-2026-34394). Confidential information can be exposed externally.
|
| CVE-2026-34395 |
|
Vulnerability in wwbn (CVE-2026-34395)
vulnerability in wwbn (CVE-2026-34395). Confidential information can be exposed externally.
|
| CVE-2026-34396 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-34396)
cross-site scripting in csrf (CVE-2026-34396). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34381 |
|
Vulnerability in apache (CVE-2026-34381)
vulnerability in apache (CVE-2026-34381). Confidential information can be exposed externally.
|
| CVE-2026-34372 |
|
Vulnerability in symfony (CVE-2026-34372)
vulnerability in symfony (CVE-2026-34372). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34204 |
|
Authentication Bypass in minio (CVE-2026-34204)
authentication bypass in minio (CVE-2026-34204). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30520 |
|
SQL Injection in sqli (CVE-2026-30520)
SQL injection in sqli (CVE-2026-30520). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2123 |
|
Vulnerability in privilege-escalation (CVE-2026-2123)
vulnerability in privilege-escalation (CVE-2026-2123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5203 |
|
Path Traversal in path-traversal (CVE-2026-5203)
path traversal in path-traversal (CVE-2026-5203). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22561 |
|
Vulnerability in privilege-escalation (CVE-2026-22561)
vulnerability in privilege-escalation (CVE-2026-22561). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34200 |
|
Vulnerability in nhost (CVE-2026-34200)
vulnerability in nhost (CVE-2026-34200). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5198 |
|
Vulnerability in sqli (CVE-2026-5198)
vulnerability in sqli (CVE-2026-5198). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2370 |
|
Vulnerability in gitlab (CVE-2026-2370)
vulnerability in gitlab (CVE-2026-2370). Confidential information can be exposed externally. Mitigation: upgrade to `18.8.7, 18.9.3, 18.10.1` or later.
|
| CVE-2026-3055 KEV |
|
[KEV] Out-of-Bounds Read in Citrix netscaler (CVE-2026-3055)
vulnerability in Citrix netscaler (CVE-2026-3055). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-27309 |
|
Use-After-Free in adobe (CVE-2026-27309)
vulnerability in adobe (CVE-2026-27309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34046 |
|
Vulnerability in langflow (CVE-2026-34046)
vulnerability in langflow (CVE-2026-34046). Successful exploitation can lead to full system takeover. Exploitable via ``_read_flow``.
|
| CVE-2026-30567 |
|
Cross-Site Scripting (XSS) in ahsanriaz26gmailcom (CVE-2026-30567)
cross-site scripting in ahsanriaz26gmailcom (CVE-2026-30567). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56358 |
|
Cross-Site Scripting (XSS) in n8n (CVE-2026-56358)
cross-site scripting in n8n (CVE-2026-56358). Risk of unauthorized operations or information disclosure. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `1.123.25` or later.
|
| CVE-2026-28367 |
|
Vulnerability in io.undertow:undertow-parent (CVE-2026-28367)
vulnerability in io.undertow:undertow-parent (CVE-2026-28367). Confidential information can be exposed externally.
|
| CVE-2026-5010 |
|
Cross-Site Scripting (XSS) in CVE-2026-5010 (CVE-2026-5010)
cross-site scripting in CVE-2026-5010 (CVE-2026-5010). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5027 |
|
Path Traversal in path-traversal (CVE-2026-5027)
path traversal in path-traversal (CVE-2026-5027). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v2/files`.
|
| CVE-2026-27877 |
|
Information Disclosure in github.com/grafana/grafana (CVE-2026-27877)
vulnerability in github.com/grafana/grafana (CVE-2026-27877). Confidential information can be exposed externally. Mitigation: upgrade to `11.6.14, 12.1.10, 12.2.8, 12.3.6, 12.4.2` or later.
|
| CVE-2026-27880 |
|
Out-of-Bounds Write in grafana (CVE-2026-27880)
out-of-bounds write in grafana (CVE-2026-27880). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.1.10, 12.2.8, 12.3.6, 12.4.2` or later.
|
| CVE-2026-27876 |
|
Code Injection in grafana (CVE-2026-27876)
code injection in grafana (CVE-2026-27876). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `11.6.14, 12.1.10, 12.2.8, 12.3.6, 12.4.2` or later.
|
| CVE-2025-53521 KEV |
|
[KEV] Vulnerability in F5 big-ip (CVE-2025-53521)
vulnerability in F5 big-ip (CVE-2025-53521). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-30463 |
|
SQL Injection in sqli (CVE-2026-30463)
SQL injection in sqli (CVE-2026-30463). Confidential information can be exposed externally.
|
| CVE-2026-30458 |
|
Vulnerability in thedaylightstudio (CVE-2026-30458)
vulnerability in thedaylightstudio (CVE-2026-30458). Confidential information can be exposed externally.
|
| CVE-2026-30457 |
|
Code Injection in thedaylightstudio (CVE-2026-30457)
code injection in thedaylightstudio (CVE-2026-30457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4897 |
|
Vulnerability in dos (CVE-2026-4897)
vulnerability in dos (CVE-2026-4897). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4809 |
|
Unrestricted File Upload in laravel (CVE-2026-4809)
vulnerability in laravel (CVE-2026-4809). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33634 KEV |
|
[KEV] Vulnerability in github.com/aquasecurity/trivy (CVE-2026-33634)
vulnerability in github.com/aquasecurity/trivy (CVE-2026-33634). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `0.35.0` or later.
|